CVE-2026-84289: NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation
A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function listtools of the file tools/mcptool.py of the component MCP Tool. Performing a manipulation results in uncontrolled memory allocation. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
NousResearch hermes-agent versions up to and including 0.18.2 are affected, specifically the MCP Tool component's tools/mcp_tool.py list_tools function. The issue can be initiated remotely.
What access does an attacker need?
The supplied CVSS vector indicates low privileges are required and no user interaction is needed. Exploitation is assessed as low complexity over the network.
What is the likely impact?
The reported result is uncontrolled memory allocation, with availability impact rated low. The provided assessment reports no confidentiality or integrity impact.
How urgent is mitigation?
A public exploit is reported to exist, and the vendor reportedly did not respond to early disclosure contact. Prioritize limiting remote access to the affected MCP Tool where possible until a vendor fix or validated update is available.